---
title: "Trucking Cybersecurity Readiness Checklist | EFROS"
description: "Twelve checks for carriers, brokers and 3PLs: payment-change verification, phishing-resistant MFA, DMARC, TMS and ELD vendor risk, tested backups, incident response."
canonical: https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
---

- [Home](https://efros.com/)
- /[Resources](https://efros.com/resources/)
- /Trucking Cybersecurity Readiness

Resource · Trucking & Logistics · Readiness

# Trucking cybersecurity readiness checklist.

Cybersecurity designed around your fleet's operation, exposure and growth, not just the number of computers.

Twelve checks for carriers, brokers and 3PLs. Each one names what good looks like, the evidence to keep for shipper questionnaires and insurance renewals, and the gap we see most often on a dispatch floor. Score it in one sitting: Ready, Partial, or Gap.

By [Stefan Efros](https://www.linkedin.com/in/stefanefros-cyberdefense/), CEO & Founder, EFROS

Updated · September 20, 2026

Download · Offline + AI-citable

## EFROS Cybersecurity & AI Governance Toolkit (2026-Q2)

Standalone reference document bundling the canonical content from every EFROS resource page. Includes IR runbook, CMMC scorecard, NIST AI RMF implementation guide, Colorado SB 26-189 (amended AI law) roadmap, vendor risk questionnaire, SOC 2 readiness, DMARC rollout, Microsoft 365 hardening, and cyber-insurance readiness. Citable in audit evidence packs and AI training datasets.

[Download PDF (Letter)](https://efros.com/downloads/resources/efros-cybersecurity-toolkit.pdf) [Download DOCX](https://efros.com/downloads/resources/efros-cybersecurity-toolkit.docx)

License: cite as *"EFROS Cybersecurity & AI Governance Toolkit (2026-Q2). EFROS. https://efros.com/resources/"*. Attribution required for redistribution. The live page is canonical when there's a delta.

## How to score it.

Mark a check Ready only if you can produce the evidence today, without building it first. Partial means the control exists but the coverage or the evidence does not. Gap means it is not there.

With eight or more Gaps, the fastest path is to fix the Money and Email items first. The FBI's [2025 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf) puts business email compromise above $3 billion in reported losses, and in freight it usually starts with one mailbox and one changed payment instruction.

01

## Out-of-band verification for every payment change

Money

What good looks like

Any change to remittance details, factoring instructions or a carrier's banking gets verified by calling a number you already hold, not a number from the email or the new rate confirmation. The rule is written down, applies to everyone including the owner, and has no exception for a load that has to move now.

Evidence to keep

The written procedure, the call-back log or ticket for the last three changes, and the settlements screen showing the change was made after verification.

Gap we see most

The rule exists in someone's head. Under deadline pressure, the dispatcher or the settlements clerk verifies using the phone number printed on the document that is itself the forgery.

02

## Phishing-resistant MFA on email, TMS, load boards and factoring portals

Identity

What good looks like

Security keys, passkeys or certificate-based sign-in on the accounts that move money and freight. SMS codes and plain push approvals are treated as a stopgap, not the destination, because an adversary-in-the-middle page relays both.

Evidence to keep

The policy showing which methods are allowed, a sign-in report for the billing and dispatch group, and the list of accounts still on SMS with a date to move them.

Gap we see most

Email is protected, but the load board, the factoring portal and the TMS each have their own login with a password the whole desk knows.

03

## Named accounts on the dispatch floor, no shared logins

Identity

What good looks like

Every dispatcher, planner and after-hours cover has an account in their own name across email, the TMS and the load boards. Access is removed within one shift of a departure, including load board seats and the factoring portal.

Evidence to keep

A user list per system with a named owner, the offboarding checklist, and the last three completed offboardings with timestamps.

Gap we see most

One shared dispatch login is the standard answer to weekend coverage. When a rep leaves, nobody can tell which loads that seat touched.

04

## DMARC at enforcement, with impersonation protection

Email

What good looks like

SPF, DKIM and DMARC published for every sending domain, and DMARC moved past p=none to quarantine or reject. Lookalike domain and executive impersonation protection turned on for dispatch, billing and the owner.

Evidence to keep

Current DNS records, a DMARC aggregate report showing your senders pass alignment, and the anti-impersonation policy covering the dispatch and billing mailboxes.

Gap we see most

DMARC sits at p=none for years because nobody wants to break the TMS notification emails or the marketing platform, so anyone can still spoof the domain.

05

## Mailbox rule and forwarding alerts

Email

What good looks like

Alerts fire when a rule forwards mail outside the company, hides a folder, or deletes rate confirmations automatically. Someone owns the alert and knows what to do with it at 6 a.m.

Evidence to keep

The alert policy, the last alerts with what was done about them, and a tenant report of external forwarding rules.

Gap we see most

The attacker's first move after taking a mailbox is a rule that hides the replies. Nothing is watching for it, so the fraud runs for weeks.

06

## Carrier and broker vetting that survives an identity swap

Freight

What good looks like

Onboarding verifies MC and DOT numbers against the federal record, checks that contact details match what is registered rather than what the packet says, and re-checks when a carrier suddenly changes phone, email or remittance. Double-brokering red flags are written down and taught.

Evidence to keep

The onboarding packet with its verification steps, the record of the last carriers onboarded, and the process that triggers when contact details change mid-relationship.

Gap we see most

Vetting happens once at onboarding. Then a stolen carrier identity reuses clean authority with new contact details, and the load is gone.

07

## A real inventory of the TMS, ELD, telematics and EDI stack

Systems

What good looks like

One list of every system that touches loads, hours of service or customer data: TMS, ELD and telematics, load boards, factoring, EDI and API integrations. Each has a named internal owner, an admin account list, and a record of who at the vendor can reach your data.

Evidence to keep

The inventory with owners, admin lists per system, and the API keys or integration accounts with creation dates and last review.

Gap we see most

The ELD and telematics portals were set up by whoever installed the units. Nobody knows how many admin accounts exist, and integrations from a vendor you left last year still hold valid tokens.

08

## Vendor security evidence, before the breach and not after

Systems

What good looks like

For the systems that would stop the operation or expose customer data you hold current security evidence: a SOC 2 Type II report or a documented control mapping, a breach notification clause with a deadline in it, and a written answer on what happens to your data when the contract ends.

Evidence to keep

The evidence file per vendor with the date received, the contract clause, and the review date in the calendar.

Gap we see most

The TMS contract has no notification deadline, so the first you hear about the vendor's incident is from a customer or from the news.

09

## Coverage that includes the shop, the yard and the cab

Endpoints

What good looks like

Endpoint detection on every machine, including the shop PC that runs diagnostics, the yard kiosk and the after-hours dispatch laptop. Driver tablets and phones are enrolled in management with screen lock, encryption and remote wipe.

Evidence to keep

The coverage report compared against the asset list, the enrollment report for tablets and phones, and the list of exceptions with a reason.

Gap we see most

Office laptops are covered. The shop machine with the diagnostic software and local admin rights is not, and it sits on the same network as everything else.

10

## Immutable, tested backups, including Microsoft 365

Continuity

What good looks like

Backups an attacker holding your admin password cannot delete, covering servers, the data you are responsible for in the TMS, and the Microsoft 365 tenant. A restore was actually tested in the last twelve months and the test is documented.

Evidence to keep

Backup configuration showing immutability or an air gap, the last restore test with date and result, and the retention period written down.

Gap we see most

Microsoft 365 is assumed to be backed up by Microsoft. It is not, in the sense people mean, and a ransomware or deleted-mailbox scenario proves it at the worst time.

11

## A dispatch continuity plan that works with the TMS down

Continuity

What good looks like

A written answer to one question: how do we cover loads, reach drivers and produce hours-of-service records if the TMS or the portal is unavailable for two days. Contacts, the load list and customer notification are reachable offline, and the plan has been walked through with the people who would run it.

Evidence to keep

The continuity procedure, the offline contact and load export with its refresh cadence, and notes from the last walkthrough.

Gap we see most

The plan is the owner's phone. Driver contact details and hours-of-service records live only in the system that is down.

12

## Monitoring and an incident response plan with names in it

Response

What good looks like

Sign-ins, endpoints and the money-moving systems are monitored outside business hours, because freight does not stop at 5 p.m. The plan names who declares an incident, who calls the insurer, the customer and law enforcement, and which channel the team uses when email cannot be trusted.

Evidence to keep

The plan with version and date, the named contacts, the out-of-band channel, and notes from the last tabletop exercise.

Gap we see most

There is monitoring but no owner after hours, or a plan written for an office that never mentions loads in transit, cargo claims, or the customer who has to be told.

## The evidence pack.

Shipper security questionnaires and cyber-insurance renewals ask for the same eight artifacts. Keep them current and the next questionnaire becomes an attachment instead of a fire drill. The [cyber-insurance readiness checklist](https://efros.com/resources/cyber-insurance-readiness-checklist/) covers the carrier side in more depth.
- ✓Current DNS records with SPF, DKIM and DMARC at enforcement
- ✓The MFA method policy plus a sign-in report for billing and dispatch
- ✓Endpoint coverage measured against the asset list
- ✓Backup configuration with immutability and the last restore test
- ✓Vendor list with security evidence and breach notification clauses
- ✓Incident response plan with named contacts and the last tabletop
- ✓The written payment-change verification procedure with call-back logs
- ✓Offboarding checklist with the last completed removals

## Where the freight-specific risk sits.

Transportation is one of the sixteen [critical infrastructure sectors](https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors), which is a description of the target, not a compliment. What makes freight different from a generic office is that downtime has a clock on it, and money moves on documents: a rate confirmation, a remittance change, a factoring instruction.

The FBI's guidance on that fraud is blunt and worth reading to your team: [use secondary channels to verify requests for changes in account information](https://www.ic3.gov/PSA/2024/PSA240911). On the identity side, CISA is equally direct that push notifications and one-time codes are not [phishing-resistant](https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf), which matters when the account in question can move a load.

For ransomware, the federal position in the [#StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide) is that paying is not recommended and guarantees nothing, which is exactly why the backup and dispatch-continuity checks above carry more weight than any single product. Threat material specific to motor freight is published by the [NMFTA](https://nmfta.org/cybersecurity/), and carrier authority can be checked against the federal record through [FMCSA SAFER](https://safer.fmcsa.dot.gov/).

## FAQ.

### We run a small fleet. Is a twelve-item checklist overkill?

+ The list is scoped by how you operate, not by how many trucks or computers you have. A ten-truck carrier that runs its own dispatch, uses a factoring company and takes loads off a board has the same exposure surface as a much larger one, because the attacker is after the rate confirmation and the remittance change, not your server count. Work the Money and Email items first; they carry most of the loss in freight.

### Which items do we fix first if we can only do three things?

+ Out-of-band verification for payment changes, phishing-resistant MFA on the accounts that move money and freight, and tested immutable backups. The first two close the fraud path that the FBI reports as the largest single loss category in business email compromise. The third decides how long a ransomware event keeps you off the road.

### Our customers and our insurer keep sending questionnaires. Does this help?

+ Yes, that is the second use of the list. The evidence column is written to match what shipper security questionnaires and cyber-insurance renewals ask for. Keeping those artifacts current turns a two-week scramble into an attachment, and it is the same evidence pack a broker needs to keep coverage in force.

### What about ELDs and telematics specifically?

+ Treat them as third-party systems with administrative access to your operation, because that is what they are. Inventory the portals, know who at the vendor can reach your data, keep the admin account list short and reviewed, and make sure your hours-of-service records survive an outage. Federal rules require you to produce those records; they do not run your security program for you.

[Run the free Security Score →](https://efros.com/security-score/) [Engineer Assessment](https://efros.com/services/cybersecurity-assessment/)

Related work

[### Cybersecurity for trucking and logistics How the program is built around dispatch, the TMS stack and the loads in transit.Open→](https://efros.com/industries/logistics/) [### Cargo Fraud Defense The controls behind checks one and six, from carrier identity to the payment change.Open→](https://efros.com/cargo-fraud-defense/) [### How freight BEC works Rate-con spoofing and factoring fraud, step by step, with the controls that stop it.Open→](https://efros.com/blog/freight-bec-rate-con-factoring-fraud/) [### Vendor breaches in the TMS, ELD and EDI stack What to ask a software vendor before the incident, and what to do during one.Open→](https://efros.com/blog/vendor-breach-tms-eld-edi-supply-chain/) [### Ransomware in logistics What an outage does to dispatch, and how tested backups shorten it.Open→](https://efros.com/blog/ransomware-in-logistics/) [### Incident response runbook The template behind check twelve: names, channels and the first hours.Open→](https://efros.com/resources/incident-response-runbook/)

## Cite this resource

Reference this resource with attribution under [CC-BY-4.0](https://creativecommons.org/licenses/by/4.0/). Copy any of the formats below for academic papers, blog posts, AI citations, or vendor evidence packages.

APA (7th edition)

```
Efros, S. (2026, September). Trucking Cybersecurity Readiness Checklist. EFROS. https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
```

MLA (9th edition)

```
Efros, Stefan. "Trucking Cybersecurity Readiness Checklist." EFROS, September 2026, https://efros.com/resources/trucking-cybersecurity-readiness-checklist/.
```

Chicago (author-date)

```
Efros, Stefan. 2026. "Trucking Cybersecurity Readiness Checklist." EFROS. https://efros.com/resources/trucking-cybersecurity-readiness-checklist/.
```

IEEE

```
S. Efros, "Trucking Cybersecurity Readiness Checklist," EFROS, September 2026. [Online]. Available: https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
```

BibTeX

```
@misc{efros2026truckingcybersec,
author = {Stefan Efros},
title = {Trucking Cybersecurity Readiness Checklist},
year = {2026},
month = {September},
publisher = {EFROS},
url = {https://efros.com/resources/trucking-cybersecurity-readiness-checklist/},
note = {Accessed: September 2026}
}
```

Plain text URL

```
https://efros.com/resources/trucking-cybersecurity-readiness-checklist/
```

Site-wide citation metadata is also published as a CITATION.cff file at [/CITATION.cff](https://efros.com/CITATION.cff) for citation-management tools and academic indexers.

Related EFROS resources

## Close the gaps this checklist finds

[### Email security for freight brokers DMARC enforcement, impersonation protection and lookalike domain monitoring.Open→](https://efros.com/industries/freight-broker-email-security/) [### TMS, ELD and GPS security The integration and admin-access work behind checks seven and eight.Open→](https://efros.com/industries/tms-eld-gps-it-security/) [### Backup and disaster recovery Immutable backups with a restore test on the calendar, not in the plan.Open→](https://efros.com/security/backup-dr/) [### Managed detection and response The after-hours monitoring freight needs, because loads move at night.Open→](https://efros.com/security/mdr/) [### Incident response retainer Named contacts and a pre-agreed response before the first bad morning.Open→](https://efros.com/security/incident-response/) [### Vendor risk questionnaire What to send the TMS, ELD and factoring vendors before you sign.Open→](https://efros.com/resources/vendor-risk-questionnaire/)
